04 / Evidence and data handling
Know what was recorded—and what was not.
Work timelines and administrative activity help reviewers understand what happened. Audit coverage, evidence capture, exports, and retention depend on policy, permissions, and enabled features.
01Administrative and agent evidence
The security ledger records covered administrative changes and supports CSV exports. Agent Audit View, where enabled, shows recorded runs, actions, outcomes, coverage indicators, and capture gaps. Full evidence must have been captured to be available for review.
02Retention and exports
Configure supported retention for messages, files, and run history. Audit evidence has its own policy, and required operational and usage records may be retained. Cleanup does not remove copies at external providers or previously downloaded exports.
03Files, execution, and network controls
Covered files stay unavailable until scanning clears them, subject to source policy and scanner configuration. Optional sandbox compute separates code execution from the application. Isolation and destination validation vary by execution path and must be reviewed in the deployment.